13 Penetration Testing jobs in Singapore
Security Engineer
Job Viewed
Job Description
Avensys is a reputed global IT professional services company headquartered in Singapore. Our service spectrum includes enterprise solution consulting, business intelligence, business process automation and managed services. Given our decade of success we have evolved to become one of the top trusted providers in Singapore and service a client base across banking and financial services, insurance, information technology, healthcare, retail, and supply chain.
We are currently looking to hire Security Engineer. This is an exciting opportunity to expand your skill set, achieve job satisfaction and work-life balance. More details as below.
Roles and Responsibilities
The Cyber Security consultant will design, implement, test, document, and hand over security solutions with a focus on Security by Design principles. The role includes deploying and managing virtual and physical firewalls, forward and reverse proxy, network security policy management and automation, endpoint security, vulnerability management and zero trust network access solution across AWS and Azure environments. Additionally, the engineer will use Terraform and other IaC tools to automate security infrastructure, conduct various security tests (SSAT, OSAT, IAT, UAT), and perform system hardening to safeguard systems against vulnerabilities.
· Security by Design: Integrate security into all stages of system design and development. Perform risk assessments and threat modelling when required.
· Implementation & Automation: Deploy firewall, proxy, endpoint and network security solutions. Automate security infrastructure with Terraform and maintain consistent security deployments.
· Testing & Hardening: Conduct System Security Acceptance Testing (SSAT), Operational Security Acceptance Testing (OSAT), Integration Acceptance Testing (IAT), User Acceptance Testing (UAT), and system hardening to ensure secure configurations.
Documentation & Handover: Create detailed documentation for security controls and processes. Provide training and handover to the operations team, with operational guides for security management.
Develop, architect, and deploy network firewall appliances from leading vendors such as Palo Alto Networks, Check Point Software Technologies, and Fortinet, ensuring robust perimeter security and threat prevention tailored to organizational needs.
Design and implement forward and reverse proxy solutions utilizing SkyHigh Secure Web Gateway, enhancing web traffic security, content filtering, and data loss prevention across enterprise networks.
Architect and integrate network security policy management solutions using AlgoSec, automating policy orchestration, optimizing firewall rules, and ensuring compliance across hybrid network environments.
Engineer and deploy Zero Trust security architectures leveraging Zscaler and Palo Alto Networks solutions, enforcing strict identity verification and least-privilege access controls to secure user and application interactions.
· Security by Design: Integrate security into all stages of system design and development. Perform risk assessments and threat modelling when required.
· Implementation & Automation: Deploy firewall, proxy, endpoint and network security solutions. Automate security infrastructure with Terraform and maintain consistent security deployments.
· Testing & Hardening: Conduct System Security Acceptance Testing (SSAT), Operational Security Acceptance Testing (OSAT), Integration Acceptance Testing (IAT), User Acceptance Testing (UAT), and system hardening to ensure secure configurations.
Documentation & Handover: Create detailed documentation for security controls and processes. Provide training and handover to the operations team, with operational guides for security management.
WHAT'S ON OFFER
You will be remunerated with an excellent base salary and entitled to attractive company benefits. Additionally, you will get the opportunity to enjoy a fun and collaborative work environment, alongside a strong career progression.
To submit your application, please apply online or email your UPDATED CV in Microsoft Word format to Your interest will be treated with strict confidentiality.
CONSULTANT DETAILS
Consultant Name: Deepa Shivakoti
Reg No: R1765546
Avensys Consulting Pte Ltd
EA Licence 12C5759
Privacy Statement: Data collected will be used for recruitment purposes only. Personal data provided will be used strictly in accordance with the relevant data protection law and Avensys' privacy policy .
Tell employers what skills you haveManaged Services
Process Automation
Azure
Vulnerability Management
Cyber Security
Architect
Information Technology
Security Management
Reverse Proxy
Hardening
Prevention
Microsoft Word
Orchestration
Loss Prevention
Acceptance Testing
Network Security
Job No Longer Available
This position is no longer listed on WhatJobs. The employer may be reviewing applications, filled the role, or has removed the listing.
However, we have similar jobs available for you below.
Penetration Testing Specialist
Posted today
Job Viewed
Job Description
As a Penetration Testing Specialist, reporting to the Internal Audit function, you will play a critical role in evaluating the organization's cybersecurity posture by simulating real-world attacks and identifying vulnerabilities across systems, applications, and networks. Your work directly supports audit objectives by validating the effectiveness of security controls, ensuring regulatory compliance, and mitigating operational risks.
Key Responsibility
- Conduct comprehensive penetration tests on applications, databases, systems and networks to identify security vulnerabilities, and prepare a detail report on the findings.
- Propose measures to ensure that identified vulnerabilities are addressed.
- Work closely with IT, risk, and compliance teams to track remediation efforts and verify closure.
- Simulate cyber attacks to evaluate defensive measures and improve security posture.
- Minimum 5 years of hands-on penetration testing experience for web applications, mobile applications, APIs, network, databases and load testing.
- Experience conducting secure code review.
- Degree in computer science/computer engineering/information security or equivalent.
- Working knowledge of all aspects of information security is essential.
- Familiarity with systems and operational architecture of large internet companies or online business models.
- Good communication (spoken and written) skills, able to work independently and as a team.
- Certifications from either GIAC/Offensive Security/CREST required.
- Hands on experience in Kali Linux, Burp, and other advanced penetration testing, and secure code review tools.
- Good to have: Basic Mandarin skills for simple verbal and written communication with Chinese partners.
关于职位
作为一名向内部审计部门汇报的渗透测试专家,您将在评估组织的网络安全态势方面发挥关键作用,通过模拟真实攻击并识别系统,应用程序和网络中的漏洞。您的工作将通过验证安全控制措施的有效性,确保合规性并降低运营风险,直接支持审计目标。
主要职责
- 对应用程序,数据库,系统和网络进行全面的渗透测试,以识别安全漏洞,并撰写详细的调查报告。
- 提出措施,确保已识别的漏洞得到解决。
- 与IT,风险和合规团队紧密合作,跟踪修复工作并验证漏洞已关闭。
- 模拟网络攻击,评估防御措施并提升安全态势。
- 至少5年Web应用程序,移动应用程序,API,网络,数据库和负载测试的渗透测试经。
- 具备安全代码审查经验。
- 计算机科学/计算机工程/信息安全或同等学历。
- 具备信息安全各方面的工作知识。
- 熟悉大型互联网公司或在线商业模式的系统和运营架构。
- 良好的沟通能力,能够独立工作和团队合作。
- 需持有GIAC/Offensive Security/CREST认证。
- 具有 Kali Linux,Burp 和其他高级渗透测试及安全代码审查工具的实践经验。
- 加分项:具备基础中文能力,能够进行简单的口头和书面沟通。
Penetration Testing Specialist
Posted today
Job Viewed
Job Description
About the Role
As a Penetration Testing Specialist, reporting to the Internal Audit function, you will play a critical role in evaluating the organization's cybersecurity posture by simulating real-world attacks and identifying vulnerabilities across systems, applications, and networks. Your work directly supports audit objectives by validating the effectiveness of security controls, ensuring regulatory compliance, and mitigating operational risks.
Key Responsibility
- Conduct comprehensive penetration tests on applications, databases, systems and networks to identify security vulnerabilities, and prepare a detail report on the findings.
- Propose measures to ensure that identified vulnerabilities are addressed.
- Work closely with IT, risk, and compliance teams to track remediation efforts and verify closure.
- Simulate cyber attacks to evaluate defensive measures and improve security posture.
Requirements
- Minimum 5 years of hands-on penetration testing experience for web applications, mobile applications, APIs, network, databases and load testing.
- Experience conducting secure code review.
- Degree in computer science/computer engineering/information security or equivalent.
- Working knowledge of all aspects of information security is essential.
- Familiarity with systems and operational architecture of large internet companies or online business models.
- Good communication (spoken and written) skills, able to work independently and as a team.
- Certifications from either GIAC/Offensive Security/CREST required.
- Hands on experience in Kali Linux, Burp, and other advanced penetration testing, and secure code review tools.
- Good to have: Basic Mandarin skills for simple verbal and written communication with Chinese partners.
渗透测试专家
关于职位
作为一名向内部审计部门汇报的渗透测试专家,您将在评估组织的网络安全态势方面发挥关键作用,通过模拟真实攻击并识别系统、应用程序和网络中的漏洞。您的工作将通过验证安全控制措施的有效性、确保合规性并降低运营风险,直接支持审计目标。
主要职责
- 对应用程序、数据库、系统和网络进行全面的渗透测试,以识别安全漏洞,并撰写详细的调查报告。
- 提出措施,确保已识别的漏洞得到解决。
- 与IT、风险和合规团队紧密合作,跟踪修复工作并验证漏洞已关闭。
- 模拟网络攻击,评估防御措施并提升安全态势。
职位要求
- 至少5年Web应用程序、移动应用程序、API、网络、数据库和负载测试的渗透测试经。
- 具备安全代码审查经验。
- 计算机科学/计算机工程/信息安全或同等学历。
- 具备信息安全各方面的工作知识。
- 熟悉大型互联网公司或在线商业模式的系统和运营架构。
- 良好的沟通能力,能够独立工作和团队合作。
- 需持有GIAC/Offensive Security/CREST认证。
- 具有 Kali Linux、Burp 和其他高级渗透测试及安全代码审查工具的实践经验。
- 加分项:具备基础中文能力,能够进行简单的口头和书面沟通。
Information Security
Transaction Processing
Remediation
Oracle SQL
Mainframe
Assessor
Penetration Testing
Mobile Applications
DB2
Web Applications
Kali Linux
Small Business
Mortgage Banking
Databases
Field Work
Audit
Penetration Testing Consultant
Posted 1 day ago
Job Viewed
Job Description
We are seeking a highly skilled and experienced penetration testing Consultant. In this role, you will be responsible for executing technical security assessments.
Responsibilities:· Perform technical security assessment engagements for clients including penetration testing, host configuration reviews, secure code reviews, etc
· Contribute to the development and enhancement of assessment methodologies
· Participate in the development of new services
Requirements:· Bachelor's degree in computer science, cybersecurity, or related field
· Professional certifications: OSCP, CRT
· 3+ years of experience in penetration testing or a related field
· Knowledge of penetration testing methodologies, tools and frameworks
· Experience with network (wired and wireless) and application (web, mobile, thick) security testing
Viewed Favorably:· Credited with CVEs
· Participates in bug bounty programs
· Organizes or participates in CTFs
· Delivers technical research at security conferences
Penetration Testing Specialist
Posted 4 days ago
Job Viewed
Job Description
About the Role
As a Penetration Testing Specialist, reporting to the Internal Audit function, you will play a critical role in evaluating the organization’s cybersecurity posture by simulating real-world attacks and identifying vulnerabilities across systems, applications, and networks. Your work directly supports audit objectives by validating the effectiveness of security controls, ensuring regulatory compliance, and mitigating operational risks.
Key Responsibility
- Conduct comprehensive penetration tests on applications, databases, systems and networks to identify security vulnerabilities, and prepare a detail report on the findings.
- Propose measures to ensure that identified vulnerabilities are addressed.
- Work closely with IT, risk, and compliance teams to track remediation efforts and verify closure.
- Simulate cyber attacks to evaluate defensive measures and improve security posture.
Requirements
- Minimum 5 years of hands-on penetration testing experience for web applications, mobile applications, APIs, network, databases and load testing.
- Experience conducting secure code review.
- Degree in computer science/computer engineering/information security or equivalent.
- Working knowledge of all aspects of information security is essential.
- Familiarity with systems and operational architecture of large internet companies or online business models.
- Good communication (spoken and written) skills, able to work independently and as a team.
- Certifications from either GIAC/Offensive Security/CREST required.
- Hands on experience in Kali Linux, Burp, and other advanced penetration testing, and secure code review tools.
- Good to have: Basic Mandarin skills for simple verbal and written communication with Chinese partners.
渗透测试专家
关于职位
作为一名向内部审计部门汇报的渗透测试专家,您将在评估组织的网络安全态势方面发挥关键作用,通过模拟真实攻击并识别系统、应用程序和网络中的漏洞。您的工作将通过验证安全控制措施的有效性、确保合规性并降低运营风险,直接支持审计目标。
主要职责
- 对应用程序、数据库、系统和网络进行全面的渗透测试,以识别安全漏洞,并撰写详细的调查报告。
- 提出措施,确保已识别的漏洞得到解决。
- 与IT、风险和合规团队紧密合作,跟踪修复工作并验证漏洞已关闭。
- 模拟网络攻击,评估防御措施并提升安全态势。
职位要求
- 至少5年Web应用程序、移动应用程序、API、网络、数据库和负载测试的渗透测试经。
- 具备安全代码审查经验。
- 计算机科学/计算机工程/信息安全或同等学历。
- 具备信息安全各方面的工作知识。
- 熟悉大型互联网公司或在线商业模式的系统和运营架构。
- 良好的沟通能力,能够独立工作和团队合作。
- 需持有GIAC/Offensive Security/CREST认证。
- 具有 Kali Linux、Burp 和其他高级渗透测试及安全代码审查工具的实践经验。
- 加分项:具备基础中文能力,能够进行简单的口头和书面沟通。
Security Consultant (Penetration Testing)
Posted 10 days ago
Job Viewed
Job Description
The Security Consultant delivers penetration testing & offensive security projects to ensure a successful
outcome that at least meets or exceeds the expectations of our clients.
Role Outcomes:- The customer recognises you as a subject matter expert and they have confidence in the comprehensiveness of the testing methodology and the accuracy of the results.
- The client has prepared the testing environment prior to the project start date so that the engagement is executed smoothly and without delay.
- Penetration testing projects are delivered efficiently and on schedule.
- The quality of the Penetration Testing Report by ensuring it has been peer reviewed and approved for release to the client.
- All client data is managed in strict accordance with Vantage Point Security data security and protection policies throughout the project.
Penetration Tester - Cloud VAPT (Vulnerability Assessment and Penetration Testing)
Posted 10 days ago
Job Viewed
Job Description
Job Description:
- Need to have experience good experience in the specific Penetration Testing.
- Experience in Vulnerability Assessment, and Offensive Security.
- Proficient in network, web application, and API testing.
- Good communication skills.
- Mandatory to have OSCP Certification.
Also require certification in :
- AWS Certified Security Specialization
- AWS Certified Solutions Architect – Associate
- AWS Certified Solutions Architect – Professional
- AWS Certified Cloud Practitioner.
Security Testing Specialist
Posted 7 days ago
Job Viewed
Job Description
Join to apply for the Security Testing Specialist role at OCBC .
Who We Are
As Singapore’s longest established bank, we have been dedicated to enabling individuals and businesses to achieve their aspirations since 1932. We provide support, services, solutions, and career paths tailored to our clients’ needs.
Today, we’re on a journey of transformation, leveraging technology and creativity to become a future-ready learning organisation. Our strategic ambition is to be Asia’s leading financial services partner for a sustainable future.
We invite you to build the bank of the future, innovate in financial services, work in supportive teams, and build lasting value in your community. Enjoy a vibrant, future-ready career with us.
Your Opportunity Starts Here.
Why Join
Protecting our customers' assets and data is central to our mission. As a Security Testing Specialist, you'll play a key role in safeguarding our systems from cyber threats, shaping the future of cybersecurity in finance.
How you succeed
Stay ahead of emerging threats, collaborate with engineering teams to identify and mitigate risks, and develop strategies to enhance cybersecurity.
What you do
- Perform application penetration testing on web-based applications, APIs
- Conduct mobile application penetration testing across platforms
- Perform network penetration testing
- Exploit vulnerabilities to assess security risks
- Document security issues and recommend mitigations
- Research latest security topics and attack vectors
- Conduct compliance testing per standards like MAS TRMG
- Perform secure code reviews when needed
- Conduct thick client penetration testing as required
- Minimum 3 years of hands-on penetration testing experience
- Experience with secure code review
- Degree in computer science, security, or related field
- Knowledge of all aspects of information security
- Familiarity with MAS TRMG and regulatory requirements
- Strong communication skills, able to work independently and in teams
- Certifications from GIAC, Offensive Security, CREST
- Hands-on experience with Kali Linux, Burp Suite, Tenable, and similar tools
- Experience conducting penetration testing for banks in Singapore preferred
- Experience with legacy systems review is a plus
Be The First To Know
About the latest Penetration testing Jobs in Singapore !
Senior Cyber Security Testing Specialist
Posted 6 days ago
Job Viewed
Job Description
Select how often (in days) to receive an alert:
Senior Cyber Security Testing SpecialistSeeking a highly skilled and motivated Senior Cyber Security Testing Specialist who is skilled in application and infrastructure penetration testing, vulnerability assessment and secure code review to conduct, guide and review the work of external and cross function team security testers. In this role, you will be responsible for assessing and enhancing the security posture of the organisation’s critical applications and infrastructure through comprehensive testing, vulnerability assessment, and penetration testing techniques. Your expertise will play a crucial role in identifying security vulnerabilities and recommending risk mitigation strategies to different senior stakeholders
Make An Impact By
- Coordinate and Oversee Penetration Testing & Vulnerability Assessment Engagements:
- Manage and coordinate penetration testing and vulnerability assessment engagements with external vendors, ensuring effective communication and collaboration between internal stakeholders and vendors.
- Work closely with Domain security champions to review and tailor the scope, rules of engagement, testing methodologies, and reporting for external penetration tests and vulnerability assessments.
- Collaborate with cross-functional teams to provide guidance on Singtel's security standards, recommend best practices, and advise on effective remediation strategies.
- Review penetration testing reports, prioritize identified vulnerabilities, and coordinate efforts to address them in a timely manner.
- Track and report on the progress and outcomes of penetration testing and vulnerability assessments, ensuring that all findings are addressed appropriately.
- Maintenance of tools and Conduct Various Penetration Tests:
- Perform different types of penetration testing (e.g., AI models, application, API, Infrastructure, etc.) following recognized methodologies, including OWASP and Singtel’s internal standards, utilizing both manual and automated testing methods, as needed.
- Maintain and configure the tests required of automated testing tools to support black box and white box testing, and ensure alignment with latest industry test requirements e.g. OWASP, covering all forms of technologies e.g. Cloud Apps, On-prem Apps, COTS products, In-house developed Apps, AI models, APIs, OS, DB, VM, Network devices, etc.
- Identify gaps in automated testing tools and propose new tooling required to augment testing program as needed
- Bug Bounty Program Management:
- Oversee and manage the bug bounty program and associated platforms for identifying and addressing reported vulnerabilities.
- Validate/ triage the reported vulnerabilities, assess their impact on Singtel’s systems, and collaborate with relevant stakeholders to prioritize and remediate the issues.
- Track and report on findings and outcomes from the bug bounty program to ensure timely resolution.
- Develop engaging programs to boost the visibility and popularity of Singtel's bug bounty program.
- Manage and conduct secure code reviews using scanning tools and techniques to identify security weaknesses in software code.
- Analyze the results from code scans and work closely with development teams to implement necessary security fixes.
- Assist in the creation and implementation of secure coding practices across the organization.
- Vulnerability Retesting and Documentation:
- Retest security vulnerabilities arising from various sources e.g. Bug Bounty, Penetration testing, etc. after remediation and update reports with the latest results and outcomes.
- Develop and maintain comprehensive documentation for all vulnerability assessments, secured code reviews and penetration tests, including detailed findings, methodologies, and recommendations for improvements etc.
- Stay Current with Security Trends and Threats:
- Continuously monitor the latest security trends, emerging vulnerabilities, and attack techniques to ensure that security testing methodologies and tools remain up-to-date and effective.
Skills for Success:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Attained OSCP or CREST.
- At least 5 years of experience working in Cyber and Information security field
- Solid experience in application security testing, vulnerability assessment, secure code review and penetration testing.
- Proficiency in performing AI models, API and application security testing using manual techniques, as well as utilizing runtime vulnerability testing tools and/or code review tools.
- Strong understanding of OWASP Top 10, CWE/SANS Top 25, and other common vulnerability frameworks.
- Out of which, at least 3 years experience in delivering various AI model, API, application, infrastructure penetration testing, vulnerability assessment and secure code review.
- Proficiency in performing AI model, API and application security assessment using manual techniques.
- Proficient in using and managing various security tools and products like Fortify, AppScan, Webinspect, Burp Suite, Nessus, Guardrails AI, Giskard, Moonshot, Deepcheck, Evidently, Pyrit, Adversarial Robustness Toolbox (ART), PyRIT, etc.
Rewards that Go Beyond
- Full suite of health and wellness benefits
- Ongoing training and development programs
- Internal mobility opportunities
Are you ready to say hello to BIG Possibilities?
Take the leap with Singtel to unlock new opportunities and accelerate your growth. Apply now and start your empowering career!
#J-18808-LjbffrSenior Cyber Security Testing Specialist
Posted 6 days ago
Job Viewed
Job Description
Seeking a highly skilled and motivated Senior Cyber Security Testing Specialist who is skilled in application and infrastructure penetration testing, vulnerability assessment and secure code review to conduct, guide and review the work of external and cross function team security testers. In this role, you will be responsible for assessing and enhancing the security posture of the organisation’s critical applications and infrastructure through comprehensive testing, vulnerability assessment, and penetration testing techniques. Your expertise will play a crucial role in identifying security vulnerabilities and recommending risk mitigation strategies to different senior stakeholders.
Make An Impact By
- Coordinate and Oversee Penetration Testing & Vulnerability Assessment Engagements:
- Manage and coordinate penetration testing and vulnerability assessment engagements with external vendors, ensuring effective communication and collaboration between internal stakeholders and vendors.
- Work closely with Domain security champions to review and tailor the scope, rules of engagement, testing methodologies, and reporting for external penetration tests and vulnerability assessments.
- Collaborate with cross-functional teams to provide guidance on Singtel's security standards, recommend best practices, and advise on effective remediation strategies.
- Review penetration testing reports, prioritize identified vulnerabilities, and coordinate efforts to address them in a timely manner.
- Track and report on the progress and outcomes of penetration testing and vulnerability assessments, ensuring that all findings are addressed appropriately.
- Maintenance of tools and Conduct Various Penetration Tests:
- Perform different types of penetration testing (e.g., AI models, application, API, Infrastructure, etc.) following recognized methodologies, including OWASP and Singtel’s internal standards, utilizing both manual and automated testing methods, as needed.
- Maintain and configure the tests required of automated testing tools to support black box and white box testing, and ensure alignment with latest industry test requirements e.g. OWASP, covering all forms of technologies e.g. Cloud Apps, On-prem Apps, COTS products, In-house developed Apps, AI models, APIs, OS, DB, VM, Network devices, etc.
- Identify gaps in automated testing tools and propose new tooling required to augment testing program as needed.
- Bug Bounty Program Management:
- Oversee and manage the bug bounty program and associated platforms for identifying and addressing reported vulnerabilities.
- Validate/ triage the reported vulnerabilities, assess their impact on Singtel’s systems, and collaborate with relevant stakeholders to prioritize and remediate the issues.
- Track and report on findings and outcomes from the bug bounty program to ensure timely resolution.
- Develop engaging programs to boost the visibility and popularity of Singtel's bug bounty program.
- Manage and conduct secure code reviews using scanning tools and techniques to identify security weaknesses in software code.
- Analyze the results from code scans and work closely with development teams to implement necessary security fixes.
- Assist in the creation and implementation of secure coding practices across the organization.
- Vulnerability Retesting and Documentation:
- Retest security vulnerabilities arising from various sources e.g. Bug Bounty, Penetration testing, etc. after remediation and update reports with the latest results and outcomes.
- Develop and maintain comprehensive documentation for all vulnerability assessments, secured code reviews and penetration tests, including detailed findings, methodologies, and recommendations for improvements etc.
- Stay Current with Security Trends and Threats:
- Continuously monitor the latest security trends, emerging vulnerabilities, and attack techniques to ensure that security testing methodologies and tools remain up-to-date and effective.
Skills for Success:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Attained OSCP or CREST.
- At least 5 years of experience working in Cyber and Information security field.
- Solid experience in application security testing, vulnerability assessment, secure code review and penetration testing.
- Proficiency in performing AI models, API and application security testing using manual techniques, as well as utilizing runtime vulnerability testing tools and/or code review tools.
- Strong understanding of OWASP Top 10, CWE/SANS Top 25, and other common vulnerability frameworks.
- Out of which, at least 3 years experience in delivering various AI model, API, application, infrastructure penetration testing, vulnerability assessment and secure code review.
- Proficiency in performing AI model, API and application security assessment using manual techniques.
- Proficient in using and managing various security tools and products like Fortify, AppScan, Webinspect, Burp Suite, Nessus, Guardrails AI, Giskard, Moonshot, Deepcheck, Evidently, Pyrit, Adversarial Robustness Toolbox (ART), PyRIT, etc.
Rewards that Go Beyond
- Full suite of health and wellness benefits.
- Ongoing training and development programs.
- Internal mobility opportunities.
Are you ready to say hello to BIG Possibilities?
Take the leap with Singtel to unlock new opportunities and accelerate your growth. Apply now and start your empowering career!
#J-18808-LjbffrData Protection Solutions Senior Analyst, Controls Testing - TikTok Privacy & Security- Singapore
Posted 6 days ago
Job Viewed
Job Description
TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and we also have offices in New York City, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.
Why Join UsInspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day.
We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.
Diversity & InclusionTikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.
Job Highlights- Career growth opportunity
- Flat organization
- 100+ mil users
Team introduction:
TikTok is seeking a highly adaptable and motivated Senior Analyst to bolster our data sovereignty controls testing program. As a key member of our Data Protection Solutions team, you will play a crucial role in ensuring the privacy and security of our regional data by executing on data sovereignty testing strategy and contributing to the improvement of technical controls across prioritized technology solutions.
You will collaborate closely with various teams, including Legal, Global Security, and Security Engineering, to help ensure continued compliance with data privacy regulations and the implementation of robust security measures, in all stages of solution development. This role reports to the Data Sovereignty Solutions Lead within PnS's Data Protection Solutions team.
Responsibilities:
- Stay up-to-date with evolving data sovereignty and regionalization requirements (e.g., GDPR, cross-border transfer requirements) and translate these requirements into discrete testing procedures, specific to applicable regions and controls
- Collaborate with engineers and product owners to assess systems in the design stage, providing a testing framework for short and long-term testing of applicable data sovereignty and regionalization controls, bespoke to their technologies
- After implementation, continue with ongoing testing of applicable data sovereignty and regionalization controls as products and systems expand or mature
- Where possible, develop automated testing mechanisms to reduce manual effort and increase program maturity in a sustainable manner
Minimum Qualifications:
- In-depth knowledge of data privacy regulations and standards, such as GDPR, CCPA, or other global data protection laws
- Strong understanding of:
Cross-border data transfers
Data security and data privacy concepts
Penetration testing or red team exercises
Data encryption, tokenization, masking, and redaction - Strong critical thinking and technical analysis skills to apply to documentation review or testing design
- Demonstrate ability to quickly assimilate to new knowledge and remain current on new developments in data sovereignty, data regionalization and data privacy
Preferred Qualification:
- Bachelors’ Degree or industry equivalent work experience
- Minimum 5 years experience working in cybersecurity, security engineering, or privacy engineering
- Relevant certifications:
CIPP/E
CISSP - Understanding of:
Cloud security and architecture
Privacy enhancing technologies
System design and application development practices
Common testing frameworks, such as the MITRE ATT&CK framework - Strong communication skills to collaborate with cross-functional teams (both technical and non-technical), influence without authority, and persuade priorities, objectives, and controls to stakeholders
- Demonstrated ability to work effectively in environments of ambiguity and constant change